MalBeacon

24 posts

MalBeacon banner
MalBeacon

MalBeacon

@malbeacon

Threat intelligence company, illuminating adversaries since 2017.

Beigetreten Ağustos 2021
5 Folgt271 Follower
Angehefteter Tweet
MalBeacon
MalBeacon@malbeacon·
New @Proofpoint blog: cargo theft actor spent 30 days inside DeceptionPro environment revealing: * 4 RMM tools * Malicious code signing-as-a-service * 13+ PowerShell scripts, and bank access. * HoK activity whole way. This is real adversary telemetry. Link in thread.
English
1
3
21
1.6K
MalBeacon retweetet
Threat Insight
Threat Insight@threatinsight·
Proofpoint baited a cargo/transport industry threat actor into performing its activities in a decoy environment operated by Deception.Pro for 30+ days. The result: rare, visibility into post‑compromise operations, tooling, and decision‑making. proofpoint.com/us/blog/threat…
Threat Insight tweet media
English
1
9
33
8.8K
MalBeacon
MalBeacon@malbeacon·
New @Proofpoint blog: cargo theft actor spent 30 days inside DeceptionPro environment revealing: * 4 RMM tools * Malicious code signing-as-a-service * 13+ PowerShell scripts, and bank access. * HoK activity whole way. This is real adversary telemetry. Link in thread.
English
1
3
21
1.6K
MalBeacon
MalBeacon@malbeacon·
🚨 Trojanized CPU-Z → STXRAT → PureLogs Stealer → PureHVNC → 54hrs of exfil through a hidden QEMU VM. We caught everything after. First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread #ThreatIntel #DFIR #Malware
English
3
22
95
7K
MalBeacon
MalBeacon@malbeacon·
ClickFix isn’t “just a trick”—it’s an on-ramp to hands-on-keyboard ops. We mapped EDR telemetry to a timeline tied to Velvet Tempest + activity consistent w/ Termite ransomware tradecraft. IOCs + defender takeaways inside. link in thread..
English
1
1
1
173
MalBeacon
MalBeacon@malbeacon·
Introducing: What is this stealer? A new repository that allows you to identify Stealer malware by the system information text file format commonly included in stealer malware exfiltration. Yara Rules included! Check it out and contribute! github.com/MalBeacon/what…
English
0
2
10
1.6K
MalBeacon
MalBeacon@malbeacon·
Adversary Illuminated - Operating #StealC C2: 176.124.198[.]17 Location: Frankfurt am Main, DE ASN: AS210644
English
0
0
1
314
MalBeacon
MalBeacon@malbeacon·
Adversary Illuminated - Operating #RiseProStealer C2: 193.233.132[.]74:8081/login Location: Lille, FR ASN: AS16276 OVH SAS
MalBeacon tweet media
English
0
0
1
336
MalBeacon
MalBeacon@malbeacon·
Adversary Illuminated - Operating #MarsStealer C2: test.akadns9[.]net/panel/login.php Location: Ballerup, DK ASN: AS9009 M247 Ltd
MalBeacon tweet media
English
0
0
2
0
proxylife
proxylife@pr0xylife·
#AgentTesla - .ppam > .ps1 1dd180f67644aff83f92e7e09565969c148b02b463f8750d44cf6426a6877cb5 c2' hxxp://103.147.185.68/j/p20gj/mawa/69bb7ee91c7a92b6dfa1.php Panel: hxxp://103.147.185.68/j/p20gj/login.php
proxylife tweet media
HT
2
6
22
0
MalBeacon
MalBeacon@malbeacon·
Adversary illuminated - Operating #Pony C2: global-popular[.]com/bin/panel/admin.php Location: Lagos, NG ASN: AS36873 Airtel Networks Limited #Malware #MalBeacon
MalBeacon tweet media
English
0
3
5
0
MalBeacon
MalBeacon@malbeacon·
Adversary illuminated - Operating #LokiBot C2: davidmorgann[.]com/LOLO/five/PvqDq929BSx_A_D_M1n_a.php Location: Port Harcourt, NG ASN: AS29465 MTN NIGERIA Communication limited #MalBeacon #Malware
MalBeacon tweet media
English
0
4
2
0